A closing file can be complete and still carry a changed bank account. The deed records. The wire settles somewhere else.
That is the failure pattern in real estate wire fraud. The attack does not need to beat every control. It only needs to enter the file where deadline pressure, trusted names and split records meet.
The FBI has identified real estate transactions as a BEC target. In its 2023 Internet Crime Report, FBI IC3 reported more than $2.9 billion in adjusted losses tied to BEC complaints. For title and real estate teams, the useful fact is narrower: closing wires are large transfers between parties that often have no payment history with one another.
The closing file has too many trusted senders
The exposure comes from the shape of the transaction. Buyers, sellers, agents, attorneys, lenders, escrow officers, title staff and bank personnel can all appear inside the same instruction trail.
Each party may see only a slice of the file. One person has the buyer thread. Another has the payoff letter. Another has the seller proceeds instruction. A message looks safe because the names, property address, closing date and tone all fit.
For title companies, the risk is direct. They receive and disburse funds. A wrong wire can become a claim, a lawsuit, a recovery scramble and a reputational wound that outlasts the closing.
For law firms, brokers and lenders, the exposure is different but related. Their name can give the bad instruction credibility even when they did not send the wire. The victim may be a buyer or seller, but the trust damage spreads across the file.
The altered instruction usually arrives late
The common move is a compromised or imitated mailbox tied to the deal. The fraudster watches until a bank instruction feels natural, then inserts a revised account.
It may be buyer cash to close. It may be seller proceeds. It may be a payoff or escrow disbursement. The instruction may arrive as a PDF, a forwarded email or a short note that points to an attachment.
The dangerous part is the context. The message can carry the right names, the right address and the right closing date. It does not need to look strange. It needs to look like one more closing task.
Seller proceeds are especially exposed. They may move soon after closing, and the recipient may not have an established payment history inside the paying organization. That is where a clean-looking packet can carry a bad account.
The checklist can approve the wrong evidence
Dual approval is weak when both approvers inspect the same compromised package. A callback is weak when the number comes from the message that requested the change.
A PDF can be the fraud. Email can document the fraud. None of that feels irregular if the file looks complete and the checklist is satisfied.
The human part matters. Closings reward people who remove blockers, calm clients and make the date. Fraudsters use that habit. They introduce a small change late in the process and let the deadline apply pressure.
Manual controls still matter. They fail when they depend on the same channel that carried the bad instruction.
Controls belong before release
The control record should exist before the wire desk receives a finished package. It should show the instruction history, the verified account and the evidence used when anything changed.
- Separate instruction exchange from email. Treat email as a notification channel, not the place where authoritative wiring instructions are created, changed and approved.
- Verify the account and payee together. A known buyer, seller or attorney can still be attached to the wrong bank account. The review should connect the payee, account, transaction and supporting evidence.
- Lock late changes into a higher review path. A bank change near disbursement should require more proof than an instruction received early in the file.
- Use trusted contact records created before the closing rush. Callback numbers should come from an independently maintained record, not from the message asking for the wire.
- Give approvers separate evidence. A second approval should not mean a second look at the same altered PDF. The approver should see the verification trail and the source of the contact record.
- Score the file before release. A first-time payee, last-minute account change, mismatched account owner, unusual bank destination or cross-border recipient should move the file into a different approval path.
- Train for the account-change pattern. Many dangerous messages contain no obvious spelling mistake. Staff should treat urgency, changed account details and altered communication paths as operational risk signals.
For higher-risk files, the question is not whether the message sounds like a known person. It is whether the bank account, payee, transaction context and timing fit a verified record that someone can reconstruct later.
Recovery is a race, not a control
After a fraudulent wire leaves, recovery depends on speed, bank cooperation and law enforcement escalation. Those are uncertain conditions, not a control design.
Sources consulted for this profile include FBI IC3 Internet Crime Reports through 2023, FBI public guidance on BEC and real estate transaction fraud, FinCEN materials on BEC and email account compromise, FTC consumer guidance on real estate closing scams, and payments risk materials from Nacha and the Federal Reserve.
For the next control review, pull ten recent closings and trace each payment instruction from first receipt to final approval. The useful finding is the first point where a bank account could have changed without a distinct verification event. Put friction there, before the next deadline makes the decision for you.
Questions practitioners ask
Why are title companies exposed to real estate wire fraud?
They sit near large funds, tight deadlines and several outside parties. A fraudster who alters payment instructions can redirect closing money before the error is visible.
Is a phone callback enough to verify wiring instructions?
Only if the number comes from a trusted record created outside the suspect message. Calling a number inside the email that requested the change can confirm the fraudster's own instruction.
Does dual approval prevent a fraudulent closing wire?
Not by itself. If both approvers review the same compromised instruction package, the second approval can document the wrong evidence.
Where should the control sit in the closing workflow?
The control should sit before payment release, when wiring instructions are received, changed, verified and approved. Waiting until the wire desk has a complete package may be too late.




